Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
GHSA-frvp-7c67-39w9 Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)CVE-2026-59729 Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)GHSA-4g3v-8h47-v7g6 Astro: Reflected XSS via unescaped View Transition animation propertiesGHSA-8mv7-9c27-98vc Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misorderedCVE-2026-13149 brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexityCVE-2026-14257 brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() functionCVE-2026-69152 brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arraysCVE-2026-13676 fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalizationCVE-2026-16221 Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ...CVE-2026-18446 fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authorityCVE-2026-69207 Hono: ReDoS in CORS middleware via Access-Control-Request-HeadersCVE-2026-71848 Hono: Algorithmic Complexity DoS in Language MiddlewareCVE-2026-71850 Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosureCVE-2026-69192 ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypassCVE-2026-54272 ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassificationCVE-2026-69198 ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypassGHSA-5p4m-2wfm-xmqj JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backportedCVE-2026-67213 nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ...CVE-2026-67214 nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ...GHSA-r28c-9q8g-f849 PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File DisclosureCVE-2026-69153 postcss: PostCSS: Information disclosure via crafted sourceMappingURLGHSA-f88m-g3jw-g9cj sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591GHSA-2p49-hgcm-8545 SVGO removeScripts plugin leaves some executable scripts intactCVE-2026-13697 undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directivesCVE-2026-14643 undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsingYour dependencies cross-checked against the OSV vulnerability database.
GHSA-frvp-7c67-39w9 Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)GHSA-4g3v-8h47-v7g6 Astro: Reflected XSS via unescaped View Transition animation propertiesGHSA-8mv7-9c27-98vc Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misorderedGHSA-f48w-9m4c-m7f5 Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)GHSA-3jxr-9vmj-r5cp brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsGHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashGHSA-rgw5-rvv9-x895 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationGHSA-4c8g-83qw-93j6 fast-uri vulnerable to host confusion via failed IDN canonicalizationGHSA-7p8r-x3mc-p8w7 fast-uri vulnerable to host confusion via backslash authority introducerGHSA-v2hh-gcrm-f6hx fast-uri vulnerable to host confusion via literal backslash authority delimiterGHSA-54fx-42gc-7vw4 Hono: Algorithmic Complexity DoS in Language MiddlewareGHSA-8j4g-w8fx-2239 Hono: ReDoS in CORS middleware via Access-Control-Request-HeadersGHSA-f23p-vx2j-j53r Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosureGHSA-22jq-vg5j-6vgg ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checksGHSA-4xrf-jv44-h6hh ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checksGHSA-mwp4-54f8-5fhr ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypassGHSA-5p4m-2wfm-xmqj JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backportedGHSA-28wg-ghj8-5hjv nanoid: non-secure generators can loop indefinitely with negative sizeGHSA-2v37-7h3g-55p8 nanoid: custom generators can loop indefinitely when size is zeroGHSA-fxqj-rqcc-2cmp PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unsetGHSA-r28c-9q8g-f849 PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File DisclosureGHSA-f88m-g3jw-g9cj sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591GHSA-2p49-hgcm-8545 SVGO removeScripts plugin leaves some executable scripts intactGHSA-4cwx-7wf7-3272 undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directivesGHSA-8xcm-r25x-g524 undici vulnerable to downstream response desynchronization via retry interceptorCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.